No more typing reviews! Try our Samantha, our new voice AI agent.
Evgen Gulak - PeerSpot reviewer
Head of IT Security Department at a energy/utilities company with 5,001-10,000 employees
Real User
Jan 16, 2022
Many false positives and inaccurate information, but scalable
Pros and Cons
  • "The solution is scalable, but other solutions are better."
  • "We are using Checkmarx for analyzing threats."
  • "Checkmarx needs to improve the false positives and provide more accuracy in identifying vulnerabilities. It misses important vulnerabilities."
  • "The purchase of this solution was a mistake. I would advise others to deploy the solution and to test all of the functionality before buying and do not trust the marketing from Checkmarx."

What is our primary use case?

We are using Checkmarx for analyzing threats.

We are not using the latest version of Checkmarx because we faced some issues.

What needs improvement?

Checkmarx needs to improve the false positives and provide more accuracy in identifying vulnerabilities. It misses important vulnerabilities.

SonarCube functions better in these areas.

For how long have I used the solution?

I have used Checkmarx within the last 24 months.

What do I think about the stability of the solution?

The stability of Checkmarx could improve.

I would rate the stability of Checkmarx a six out of ten.

Buyer's Guide
Checkmarx One
March 2026
Learn what your peers think about Checkmarx One. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,376 professionals have used our research since 2012.

What do I think about the scalability of the solution?

The solution is scalable, but other solutions are better.

We have 20 developers using this solution. We have a few projects left to use this solution and then we will move to something else next year.

How are customer service and support?

The support could improve, it takes a long time for a response. The service we received was poor.

Which solution did I use previously and why did I switch?

I am using Checkmarx in parallel with SonarQube.

How was the initial setup?

We didn't like how long they took to implement the product. The installation was not intuitive. We were constantly having meetings and installation additional things.

The implementation process should improve.

What about the implementation team?

We were helped by both the local partner and the vendor for the implementation.

We have two developers for the maintenance and support of Checkmarx.

What's my experience with pricing, setup cost, and licensing?

We're using a commercial version of Checkmarx, and we paid for the solution for two years. The price is high and could be reduced.

The local distributor charges two times higher than in other countries.

What other advice do I have?

The purchase of this solution was a mistake.

I would advise others to deploy the solution and to test all of the functionality before buying and do not trust the marketing from Checkmarx.

I rate Checkmarx a four out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Vice President at Arisglobal Software Pvt Ltd
Real User
Jun 23, 2020
Very good technical support, good vulnerability protection upgrades, and rich in features
Pros and Cons
  • "The solution is always updating to continuously add items that create a level of safety from vulnerabilities. It's one of the key features they provide that's an excellent selling point. They're always ahead of the game when it comes to finding any vulnerabilities within the database."
  • "The solution is always updating to continuously add items that create a level of safety from vulnerabilities, and they are always ahead of the game when it comes to finding any vulnerabilities within the database, so I am assured that when I am scanning my product those vulnerabilities are identified at very initial stages, giving my development team more time to react."
  • "In terms of dashboarding, the solution could provide a little more flexibility in terms of creating more dashboards. It has some of its own dashboards that come out of the box. However, if I have to implement my own dashboards that are aligned to my organization's requirements, that dashboarding feature has limited capability right now."
  • "Their licensing fees are rigid and this causes two main issues. One is a restriction in terms of scaling the product at an enterprise level."

What is our primary use case?

We are using it for static security scanning and static security testing. We also use it for code dependency analysis. We use two of the solution's tools for each variable.

What is most valuable?

The support the solution offers is very good. When we were evaluating tools, they were extremely helpful. They're always available and they always respond back to any queries.

The solution is always updating to continuously add items that create a level of safety from vulnerabilities. It's one of the key features they provide that's an excellent selling point. They're always ahead of the game when it comes to finding any vulnerabilities within the database. I am able to be assured that when I am scanning my product those vulnerabilities are identified at very initial stages. It gives my development team more time to react.

What needs improvement?

The particular way the tool works for the scanning at the IDE level, is very expensive. It makes it very expensive to deploy this tool on to multiple different developers' machines. Right now, the way it scans, the request is raised to the IDE of the developer but then the actual scanning gets done in the centralized scan server. This increases the load on the scanning server and that will make it difficult to use Checkmarx at the developer end. That forces me to look for another solution for implementing at the developer IDE level. I would strongly recommend Checkmarx relook into their approach. 

From a technical point of view, it's better to integrate with other systems within my ecosystem. For example, when I'm connecting Checkmarx with my DevSecOps pipeline and then wiring Checkmarx with other security systems as well as the pipeline (and my defect management system), it provides the connectivity to some of the tools, but there are tools which are excluded. It would be nice if they were added to the solution itself, otherwise, it requires us to do custom development.

In terms of dashboarding, the solution could provide a little more flexibility in terms of creating more dashboards. It has some of its own dashboards that come out of the box. However, if I have to implement my own dashboards that are aligned to my organization's requirements, that dashboarding feature has limited capability right now. I would recommend much more flexibility in terms of dashboarding to help us customize more effectively.

Their licensing model is rigid and difficult to navigate.

For how long have I used the solution?

I haven't been dealing with the solution for that long. We've only used it for one quarter - about three months.

What do I think about the scalability of the solution?

Their licensing fees are rigid and this causes two main issues. One is a restriction in terms of scaling the product at an enterprise level. The number of licenses required for a sizable business is just too large. The solution forces a user to apply for the licenses not directly to the software and the software products are defined in a curious way. For that reason, I wouldn't say it's great at scaling.

How are customer service and support?

So far, technical support at the initial level has been decent. We paid for their protection services, and, the protection tool is definitely very expensive. However, with the price tag comes more support and service. 

We'll have to see in the coming quarters once the protection services end if the support will continue to be at such a high level of attention.  

Which solution did I use previously and why did I switch?

We were using AppScan. Checkmarx is much better than that particular tool. It has more functionality and offers much more support to its users.

How was the initial setup?

It took about two to three days to deploy a basic portion of the solution. However, it takes more time in terms of configuring and fine-tuning the product so that it's useable. I would say it took us about two to three weeks of configuring before we could start our initial scans.

What about the implementation team?

We bought that separate service from Checkmarx to help us out in terms of deploying and configuring the products.

What's my experience with pricing, setup cost, and licensing?

This solution is definitely one of the more expensive tools. However, if I'm able to get value out of using it, I don't mind paying. 

They have protection services costs that are separate from the main license.

There are multiple components that are part of the product suite and there are different license costs for each of those components. Sometimes it can be a little difficult to understand. There are a lot of components an individual will need to buy to cover an organization's needs. It really should be more transparent and flexible. Their licensing model as of today is quite rigid. 

What other advice do I have?

We're just a customer. We don't have a special relationship with the company.

I would definitely recommend Checkmarx, I find them much more feature-rich than other tools I've used in the past. 

I'd rate the solution eight out of ten.

Which deployment model are you using for this solution?

Private Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Checkmarx One
March 2026
Learn what your peers think about Checkmarx One. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,376 professionals have used our research since 2012.
Java Developer at a security firm with 51-200 employees
Real User
Nov 3, 2023
Has a valuable static code analysis feature and a simple setup process
Pros and Cons
  • "The product's most valuable feature is static code and supply chain effect analysis. It provides a lot of visibility."
  • "The product's reporting feature could be better. The feature works well for developers, but reports generated to be shared with external parties are poor, it lacks the details one gets when viewing the results directly from the Checkmarx One platform."

What is our primary use case?

We use the product for static code analysis, supply chain, and container security.

What is most valuable?

The product's most valuable feature is static code and supply chain effect analysis. It provides a lot of visibility.

What needs improvement?

The product's reporting feature could be better. The feature works well for developers, but reports generated to be shared with external parties are poor, it lacks the details one gets when viewing the results directly from the Checkmarx One platform.

For how long have I used the solution?

We have been using Checkmarx's on-premise version for four years. We switched to the cloud version recently.

What do I think about the stability of the solution?

I rate the product's stability a nine or ten out of ten.

What do I think about the scalability of the solution?

We have 40 Checkmarx users in our organization. I rate its scalability a nine out of ten.

How are customer service and support?

The technical support team promptly addresses the issues.

How was the initial setup?

The initial setup process is easy.

What other advice do I have?

I rate Checkmarx an eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Pasindu Wijesinghe - PeerSpot reviewer
Software Engineer Intern at Connex Information Technologies
Real User
Mar 16, 2023
Easy to deploy, scalable, and user-friendly UI
Pros and Cons
  • "The UI is user-friendly."
  • "The plugins for the development environment have room for improvements such as for Android Studio and X code."

What is our primary use case?

We use the solution for our international customers.

What is most valuable?

The UI is user-friendly.

The Fast feature for static application security testing is the most valuable.

What needs improvement?

The plugins for the development environment have room for improvements such as for Android Studio and X code.

For how long have I used the solution?

I have been using the solution for two months.

What do I think about the stability of the solution?

I give the stability a seven out of ten.

What do I think about the scalability of the solution?

I give the scalability a nine out of ten.

The scalability is based on the number of licenses. We currently have five licenses.

How are customer service and support?

The technical support is quick to respond.

How would you rate customer service and support?

Positive

How was the initial setup?

I give the initial setup an eight out of ten. The deployment takes about ten minutes.

What about the implementation team?

The implementation was completed by a consultant.

What's my experience with pricing, setup cost, and licensing?

The solution is costly. I give the solution a six out of ten for price.

What other advice do I have?

I give the solution a nine out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Le Viet - PeerSpot reviewer
Security Consultant at VNCS
Real User
Jun 2, 2022
Minimal configuration, simple setup, and useful user interface
Pros and Cons
  • "The most valuable feature of Checkmarx is the user interface, it is very easy to use. We do not need to configure anything, we only have to scan to see the results."
  • "The most valuable feature of Checkmarx is the user interface, it is very easy to use, and we do not need to configure anything, we only have to scan to see the results."
  • "Checkmarx could improve the speed of the scans."
  • "Checkmarx could improve the speed of the scans."

What is our primary use case?

Checkmarx is used for application security, we can detect the stability and other details on how to fix issues.

What is most valuable?

The most valuable feature of Checkmarx is the user interface, it is very easy to use. We do not need to configure anything, we only have to scan to see the results.

What needs improvement?

Checkmarx could improve the speed of the scans.

For how long have I used the solution?

I have been using Checkmarx for approximately half a year.

What do I think about the scalability of the solution?

We have five people in our company that uses Checkmarx, we do not plan to increase usage.

How are customer service and support?

I have used the support from Checkmarx.

Which solution did I use previously and why did I switch?

I have not used another before Checkmarx.

How was the initial setup?

The initial setup of Checkmarx was very easy. The process took approximately one hour. We only need to provide information.

What about the implementation team?

We have five people that are supporting Checkmarx in our company.

What other advice do I have?

This solution is one of the easiest solutions I have used. We have professional services set it up for us but the scans are not enough for us.

I rate Checkmarx an eight out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1108275 - PeerSpot reviewer
Security at a tech services company with 51-200 employees
Real User
Feb 11, 2022
Gives good results, but can be more user-friendly
Pros and Cons
  • "Apart from software scanning, software composition scanning is valuable."
  • "In my opinion, Checkmarx gives better results, and its protection is better than SonarQube."
  • "Its user interface could be improved and made more friendly."
  • "Its user interface could be improved and made more friendly."

What is our primary use case?

We use it for code scanning and security testing for our in-house application development. We are using its latest version.

What is most valuable?

Apart from software scanning, software composition scanning is valuable.

What needs improvement?

Its user interface could be improved and made more friendly. 

When we change a window, the session times out, and we have to log in again. It can be improved from this aspect.

For how long have I used the solution?

I have been using this solution for about one year.

What do I think about the stability of the solution?

It has been stable during our work.

What do I think about the scalability of the solution?

We don't have so many applications. So, I have no idea about its scalability. It is enough for our work at the moment, and we have not had any problem with its scalability.

In our team, we have about 10 users.

How are customer service and support?

We are just users of this solution. There is another team that interacts with them. They get technical support from the vendor on this. 

Which solution did I use previously and why did I switch?

In my previous company, I used SonarQube. In my opinion, Checkmarx gives better results, and its protection is better than SonarQube.

How was the initial setup?

Another team takes care of its deployment. We are just users. We just log into the server and use it for scanning.

What other advice do I have?

It has been working well. I would rate it a seven out of 10.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer932058 - PeerSpot reviewer
AVP, aPaaS Engineer at a financial services firm with 10,001+ employees
Real User
Jan 10, 2022
Reasonably price, high performance, and simple installation
Pros and Cons
  • "The solution has good performance, it is able to compute in 10 to 15 minutes."
  • "The solution has good performance, it is able to compute in 10 to 15 minutes."
  • "Checkmarx could improve the REST APIs by including automation."
  • "Checkmarx could improve the REST APIs by including automation."

What is our primary use case?

We are using Checkmarx for application code scanning, such as scanning for different leverages in the application code.

What is most valuable?

The solution has good performance, it is able to compute in 10 to 15 minutes. 

What needs improvement?

Checkmarx could improve the REST APIs by including automation.

For how long have I used the solution?

I have been using Checkmarx for approximately one year.

What do I think about the stability of the solution?

Checkmarx is stable.

What do I think about the scalability of the solution?

The scalability of Checkmarx is good, we can onboard easily.

We have approximately 200 people in my organization using this solution.

How are customer service and support?

I have not contacted technical support. We have not required it.

Which solution did I use previously and why did I switch?

I have used SonarQube previously.

How was the initial setup?

The installation is straightforward and takes approximately 40 minutes.

What about the implementation team?

I am able to do the implementation myself.

We have administrators and engineers that support and maintain the solution.

What's my experience with pricing, setup cost, and licensing?

We have purchased an annual license to use this solution. The price is reasonable.

What other advice do I have?

I rate Checkmarx a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1646475 - PeerSpot reviewer
Senior Cybersecurity Solution Architect at a computer software company with 51-200 employees
Real User
Oct 17, 2021
Integrates well with other security solutions
Pros and Cons
  • "It can integrate very well with DAST solutions. So both of them are combined into an integrated solution for customers running application security."
  • "It can integrate very well with DAST solutions, so both of them are combined into an integrated solution for customers running application security."
  • "I expect application security vendors to cover all aspects of application security, including SAST, DAST, and even mobile application security testing. And it would be much better if they provided an on-premises and cloud option for all these main application security features."
  • "I expect application security vendors to cover all aspects of application security, including SAST, DAST, and even mobile application security testing."

What is our primary use case?

Checkmarx is used only for static application security testing (SAST), and it can integrate very well with DAST solutions. So both of them are combined into an integrated solution for customers running application security.

What needs improvement?

I expect application security vendors to cover all aspects of application security, including SAST, DAST, and even mobile application security testing. And it would be much better if they provided an on-premises and cloud option for all these main application security features. So most of my customers would love to have consolidated vendors who cover all application security to lower operational overhead.

For how long have I used the solution?

I'm a solution architect, not an end-user. I'm selling Checkmarx. This is the first year I've done business with Checkmarx. In the past five years, I worked a lot with Fortify and Micro Focus. I currently have two customers running Checkmarx, and one more is evaluating the product.

How was the initial setup?

Setting up Checkmarx should be relatively straightforward. It takes a little more time for the DevOps team to enable everything, but overall deployment should take less than a week, including preparation and implementation. 

What's my experience with pricing, setup cost, and licensing?

Most of my customers opted for a perpetual license. They prefer to pay the highest amount upfront for the perpetual license and then pay for additional support annually.

What other advice do I have?

I rate Checkmarx eight out of 10. Until I get more extensive feedback from clients, I would rate it an eight.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Buyer's Guide
Download our free Checkmarx One Report and get advice and tips from experienced pros sharing their opinions.
Updated: March 2026
Buyer's Guide
Download our free Checkmarx One Report and get advice and tips from experienced pros sharing their opinions.